Context

As a Business Information Security Officer for a large health-services organization, I owned cybersecurity GRC for roughly 150 applications, including 30 business-critical systems handling PHI, PII, or PCI DSS data. When I picked up the portfolio, remediation SLA compliance sat at about 65%.

The challenge

A 65% compliance rate meant roughly a third of findings were missing the timeframes the organization had committed to. Findings aged out quietly, risk acceptances accumulated without review, and there was no reliable rhythm for getting overdue items in front of the people who could act on them. The scanning was not the problem. The follow-through was. Nobody owned the gap between a finding being identified and a finding being closed, so it sat.

What I did

Outcome

SLA compliance rose from about 65% to about 99% and held there. Aged findings and unreviewed risk acceptances fell sharply, and the compliance figure became a number leadership trusted, because it measured whether the organization kept the commitments it had made rather than how much noise the scanner produced.

What it demonstrates

Running an enterprise vulnerability-remediation program to hit its commitments through ownership, review cadence, exception governance, and executive reporting, across a large portfolio of regulated, business-critical applications. For the general thinking behind the metrics used here, see vulnerability metrics leaders can act on.